Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nmap

First CVE: Oct 26, 2013Active for: 13 yearsTotal CVEs: 6

Nmap is a widely used open-source network reconnaissance and auditing tool, with a minimal but prominent vulnerability footprint centered on the core scanner and its packet-capture library, Npcap. The recurring weakness classes in its disclosures include memory-safety issues such as double-free conditions and path-traversal flaws in file handling, reflecting the low-level networking and system-interaction demands of a scanning engine. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nmap over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2013
12 years ago
Most Recent CVE
Jun 28, 2026
26 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-58058MEDIUM
Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffe
Jun 28, 20266.532NONO
CVE-2013-4885MEDIUM
The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted Ful
Oct 26, 20136.829NOYES
CVE-2018-15173HIGH
Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service.
Aug 8, 20187.527NONO
CVE-2017-18594HIGH
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.ns
Aug 29, 20197.525NONO
CVE-2019-11490HIGH
An issue was discovered in Npcap 0.992. Sending a malformed .pcap file with the loopback adapter using either pcap_sendqueue_queue() or pcap_sendqueue_transmit() results in kernel
Apr 24, 20197.825NONO
CVE-2018-1000161MEDIUM
nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite
Apr 18, 20185.719NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (16.7%)
Network4 (66.7%)
Unknown1 (16.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High0 (0.0%)
Unknown1 (16.7%)
User Interaction
None4 (66.7%)
Unknown1 (16.7%)
Required1 (16.7%)
Privileges Required
Low2 (33.3%)
High0 (0.0%)
None3 (50.0%)
Unknown1 (16.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nmap.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nmap — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nmap's Products

View all 2 CNAs →

Top CWEs